TQAY - Tech, Quality & You
Senior Full-Stack Software Engineer (AI/SaaS) – Open for Qatar Residents Only
TQAY - Tech, Quality & YouQatar20 hours ago
Full-timeEngineering, Information Technology

ABOUT TQAY

TQAY builds production-grade AI platforms, SaaS products, and secure cloud/on-prem systems for government, finance, hospitality/tourism, retail, and enterprise in Qatar. We ship end-to-end: strategy → architecture → code → security → deployment → monitoring.


ROLE SUMMARY

Own end-to-end product development across frontend, backend, data, and cloud. Implement secure OAuth integrations (Meta/WhatsApp), build RAG/search services, and deliver multi-tenant SaaS with strong security, observability, and documentation.


KEY RESPONSIBILITIES

• Ship features from spec → production with tests, telemetry, and docs

• Design secure REST/GraphQL APIs; implement RBAC/ABAC and audit trails

• Implement OAuth 2.0 (Auth Code + PKCE), webhooks, token rotation

• Build Omni-chat integrations: WhatsApp Business API, IG/FB Messenger

• Create RAG pipelines: ingest (PDF/Office/URLs), chunk, embed, vector search

• Model data in Postgres; performance tuning, migrations, indexing

• Deploy on secure private servers/VPC (on-prem or cloud), automate CI/CD

• Operate with reliability in regulated environments (logs, SLOs, incident runbooks)


TECH STACK

Frontend: React/Next.js, TypeScript, Tailwind, shadcn/ui, i18n (EN/AR)

Backend: Node.js/TypeScript, NestJS/Express, PostgreSQL, Redis/queues, WebSockets, n8n

AI/RAG: OpenAI embeddings, pgvector (Supabase/Postgres), ingestion pipelines

Cloud/DevOps: Vercel/AWS, Docker, GitHub Actions, Sentry/observability, IaC basics

Integrations: Meta OAuth/PKCE, App Review/Live Mode, WhatsApp Business API, webhooks


MUST-HAVES

• Qatar residency

• Previous experience creating a Verified Meta App (passed App Review, moved to Live Mode) MUST-HAVE for integrations

• 5–8+ years building production apps (React + Node + Postgres)

• Strong API and database design; proven SQL performance debugging

• Real OAuth 2.0 experience with (PKCE, refresh, rotation) and third-party integrations

• Shipped RAG/search features (chunking, embeddings, retrieval) or equivalent complexity

• Secure private deployment: private VPC/on-prem, network segmentation, bastion/VPN/IPsec, security groups/NACLs

• Encryption in practice: TLS/mTLS, encryption at rest (KMS/HSM), key rotation

• Secrets management (Vault/SSM/Secrets Manager); zero secrets in code/CI

• Postgres security: RLS for multi-tenancy, PITR backups, retention, masking

• Observability + auditability: structured logs, SIEM integration, alerting

• Testing culture (unit/integration), code reviews, pragmatic documentation

• Excellent communication; thrives in fast, on-site product sprints


NICE-TO-HAVES

• Supabase + pgvector at scale; Postgres tuning and partitioning

• WhatsApp/Meta webhook processors; multi-channel chat experience

• Docker/K8s hardening (CIS), image signing/SBOM, supply-chain hygiene

• GCC/Qatar data-residency patterns; tokenization/pseudonymization

• Prior GCC enterprise delivery

Key Skills

Ranked by relevance